nerdexam
Palo_Alto_Networks

XDR-ENGINEER · Question #33

A multinational company with over 300,000 employees has recently deployed Cortex XDR in North America. The solution includes the Identity Threat Detection and Response (ITDR) add-on, and the Cortex…

The correct answer is A. The XDR tenant is not in the same region as the Cloud Identity Engine. Option A is correct because the Cloud Identity Engine (CIE) was onboarded specifically to the North American tenant, meaning it is only collecting and surfacing identity data from directory services (Active Directory, LDAP, etc.) within that regional scope - European directory…

Identity Threat Detection and Response

Question

A multinational company with over 300,000 employees has recently deployed Cortex XDR in North America. The solution includes the Identity Threat Detection and Response (ITDR) add-on, and the Cortex team has onboarded the Cloud Identity Engine to the North American tenant. After waiting the required soak period and deploying enough agents to receive Identity and threat analytics detections, the team does not see user, group, or computer details for individuals from the European offices. What may be the reason for the issue?

Options

  • AThe XDR tenant is not in the same region as the Cloud Identity Engine
  • BThe Cloud Identity Engine plug-in has not been installed and configured
  • CThe Cloud Identity Engine needs to be activated in all global regions
  • DThe ITDR add-on is not compatible with the Cloud Identity Engine

How the community answered

(28 responses)
  • A
    68% (19)
  • B
    4% (1)
  • C
    11% (3)
  • D
    18% (5)

Explanation

Option A is correct because the Cloud Identity Engine (CIE) was onboarded specifically to the North American tenant, meaning it is only collecting and surfacing identity data from directory services (Active Directory, LDAP, etc.) within that regional scope - European directory data simply isn't being ingested by this tenant. Palo Alto's CIE is a region-aware service, and the XDR tenant and CIE must share the same regional context for identity enrichment to function across all directory sources feeding into that tenant.

Option B is wrong because the plugin is clearly installed and working - North American user/group/computer details are appearing, so the integration itself is functional. Option C misrepresents how CIE works - it doesn't require global activation across all regions; rather, the right CIE instance needs to be aligned with the right tenant region where the identity sources reside. Option D is factually incorrect; ITDR and Cloud Identity Engine are purpose-built to work together as part of the Cortex platform.

Memory tip: Think "same roof, same data" - the CIE can only share identity intelligence with the XDR tenant it lives alongside regionally. European employees live under a different regional "roof," so their identity data never reaches the North American tenant.

Topics

#Cloud Identity Engine#ITDR#regional tenancy#identity analytics

Community Discussion

No community discussion yet for this question.

Full XDR-ENGINEER Practice